Skip to main content
VTechFusion Technologies
The EU AI Act's High-Risk Rules: What Articles 9–17 and 26 Actually Require [Updated: Timeline Delayed]
InsightsNewsIndustry & AI News
Industry & AI News8 min readAugust 15, 2026

The EU AI Act's High-Risk Rules: What Articles 9–17 and 26 Actually Require [Updated: Timeline Delayed]

VT

VTechFusion Team

VTechFusion Technologies

Editor's correction, August 18, 2026: this article originally reported that August 2, 2026 was the binding enforcement date for the EU AI Act's high-risk obligations, and that a proposed delay had not been enacted. That has since changed — the Council of the EU and European Parliament finalized a delay on June 29, 2026. High-risk obligations under Articles 9–17 (providers) and Article 26 (deployers) now apply from December 2, 2027 (standalone systems) and August 2, 2028 (systems embedded in regulated products). See our full update for the sourced details. The rest of this article — what counts as high-risk and what the obligations actually require — remains accurate and is left as originally published below.

What Counts as "High-Risk" Under the Act

Annex III of the EU AI Act enumerates the specific domains that trigger high-risk classification: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. If your AI system operates in one of these domains and its output affects people in the EU, these obligations apply regardless of where your company is based — similar to how GDPR extended beyond EU-based companies.

What Actually Takes Effect Now

  • Risk management systems — documented, ongoing processes for identifying and mitigating risk across the AI system's lifecycle
  • Data governance — requirements on training, validation, and testing data quality and relevance
  • Technical documentation and record-keeping — sufficient for a regulator to assess compliance after the fact
  • Transparency and human oversight — including the accuracy, robustness, and cybersecurity standards a high-risk system must meet
  • Deployer obligations under Article 26 — organisations using a high-risk system carry compliance obligations too, not just the vendor that built it
  • Conformity assessment procedures and the complete market surveillance framework, including post-market monitoring and incident reporting

Update: The Delay Is Now Real — What Changed Since This Was Published

At original publication, a November 2025 European Commission proposal to delay certain deadlines to late 2027 had not been enacted into law, so this article correctly reported August 2, 2026 as binding at that time. Since then, the Council of the EU and European Parliament finalized that delay: high-risk obligations now apply from December 2, 2027 (standalone systems) and August 2, 2028 (systems embedded in regulated products), not August 2, 2026. See our full, sourced update for the details and timeline of how the delay was finalized.

What This Means If You Deploy AI in the EU

The obligations described above — risk management, documentation, deployer duties under Article 26 — have not changed, only their enforcement date has moved later. If any AI system you provide or deploy touches the domains in Annex III and affects people in the EU, these are still the requirements to build toward; you now have until December 2027 or August 2028, depending on system type, rather than August 2026. This is exactly the kind of framework our AI Governance & Compliance work is built around: risk classification first, then documentation and oversight scaled to the actual risk tier, rather than a generic policy that does not hold up to a real audit.

Filed under:Industry & AI News
All News

Frequently Asked Questions

Has the EU AI Act's high-risk deadline actually been delayed?

Yes, as of an update finalized June 29, 2026 — this article's original answer (no) reflected accurate status at the time of first publication, before the delay was enacted. High-risk obligations now apply from December 2, 2027 for standalone systems and August 2, 2028 for systems embedded in regulated products, not August 2, 2026.

Does the EU AI Act apply to companies outside the EU?

Yes, if the AI system's output is used in the EU — the Act applies extraterritorially in a similar way to GDPR, regardless of where the provider or deployer is headquartered.

What is the difference between provider and deployer obligations?

Providers (Articles 9–17) are the organisations that build and place a high-risk AI system on the market. Deployers (Article 26) are organisations that use a high-risk system in their own operations — both carry distinct compliance obligations, so using a compliant vendor product does not automatically satisfy your own obligations as a deployer.

Media & Press Enquiries

For editorial enquiries, expert commentary, or case study access.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.